mirror of
https://github.com/project-zot/zot.git
synced 2025-04-08 02:54:41 -05:00
The zap scanner started to check the csp header, which is causing a warning. We also need to ignore the rule, as both settings are read by the scanner. Per https://w3c.github.io/webappsec-csp/#example-7bb4ce67 we can have multiple Content-Security-Policy headers, and the most restrictive policies apply. This rule doesn't seem to be applied by zap. Signed-off-by: Andrei Aaron <aaaron@luxoft.com> |
||
---|---|---|
.. | ||
api | ||
cli | ||
common | ||
compliance | ||
debug | ||
exporter | ||
extensions | ||
log | ||
meta | ||
regexp | ||
requestcontext | ||
scheduler | ||
storage | ||
test |